Guide

EU Cyber Resilience Act compliance, explained for manufacturers

The CRA is the first EU law that makes cybersecurity a condition of the CE marking. Here is what it actually requires, who it applies to, and how to get compliant before the deadlines, without building a product-security team.

Who is in scope?

Every manufacturer placing a "product with digital elements" on the EU market: connected hardware (IoT devices, industrial machines, consumer electronics, smart home, wearables), embedded firmware, and software sold or licensed in the EU. Importers and distributors carry verification duties. Non-EU manufacturers exporting to the EU are fully in scope. Around 90% of products fall into the "default" category, meaning you self-assess conformity, without a notified body.

The two deadlines that matter

September 11, 2026, reporting obligations begin: actively exploited vulnerabilities and severe incidents must be notified to ENISA with an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days of a corrective measure. December 11, 2027, full compliance: CE marking requires a complete cybersecurity technical file, secure-by-design evidence, an SBOM, and a vulnerability handling process covering the product's entire support period.

What you must produce

1) A machine-readable Software Bill of Materials (SBOM) for each product. 2) A cybersecurity risk assessment and secure-by-design documentation (Annex VII technical file). 3) A coordinated vulnerability disclosure policy and a public contact point. 4) A vulnerability monitoring and patching process for the whole support lifetime. 5) An EU Declaration of Conformity. Non-compliance exposes you to fines up to €15M or 2.5% of worldwide turnover, and losing the right to sell in the EU.

A practical path to compliance

Step 1: inventory your products and classify them (default vs important class I/II). Step 2: generate SBOMs from your codebases and firmware. Step 3: match components against known vulnerabilities and set up continuous monitoring. Step 4: write (or generate) your technical file and declaration. Step 5: wire your incident response to the 24h/72h ENISA workflow before September 2026. Most manufacturers without a product-security team automate steps 2-5 with a platform rather than hiring consultants at €30-80k per product.

Want to know where your product stands today?

Generate a free CRA-ready SBOM and see the known vulnerabilities in your dependencies, free account, one minute, no credit card.

Run the free scan →

This guide is general information, not legal advice. Sources: Regulation (EU) 2024/2847 (Cyber Resilience Act), European Commission digital strategy publications, ENISA guidance.